CVE-2025-27727Exploit(microsoft / windows_10_1507)

MEDIUMCVSS 7.8 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch microsoft windows_10_1507 systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Improper link resolution before file access ('link following') in Windows Installer allows an authorized attacker to elevate privileges locally.

4.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-59

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • windows_10_1507
  • windows_10_1607
  • windows_10_1809
  • windows_10_21h2

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
windows_10_1507windows_10_1607windows_10_1809windows_10_21h2windows_10_22h2windows_11_22h2windows_11_23h2windows_11_24h2windows_server_2008windows_server_2012

2 versions affected across 15 products

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-07-06: 1PoC Mentioned / Linked · 2026-07-06: 1Exploit Tool / Code · 2026-07-06: 1Patch / Workaround · 2026-07-06: 1Technical Details · 2026-07-06: 107-06
Signal classification1 categories
Exploit
1100.0%
Full discourse1 post
  • DFIR Radar@DFIR_Radar
    Exploit

    CVE-2025-27727 in Windows Installer lets any low-privileged user escalate to SYSTEM by abusing a logic flaw in the MSI COM interface. Patched April 2025; full exploit chain published. Key findings: - The root cause is a trust-without-validation flaw in CMsiConfigurationManager, exposed via msiexec.exe running as SYSTEM. Three COM methods chained together trigger it: MsiBeginTransactionW (vtable 0xA0) starts a transaction, SetEEUIDirectoryAndFilter (vtable 0xC8) writes an attacker-controlled path to HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\TempPackages, and CleanupTempPackages (vtable 0x50) deletes that path as SYSTEM with no origin validation. The only gatekeeping is a DELETE permission check, trivially satisfied by creating C:\Config.Msi yourself. - The four-phase exploit escalates from folder-delete primitive to SYSTEM shell. The attacker re-creates C:\Config.Msi with a NULL DACL, races the installer during a triggered rollback, uses a retained WRITE_DAC handle to swap the legitimate .rbs rollback script with a malicious one, and lets msiexec execute it as SYSTEM. - The patch adds a WIL feature flag check inside CMsiTransaction::SetEEUIDirectoryAndFilter that blocks the call to ScheduleFileOrFolderDelete entirely, breaking the chain before any path reaches TempPackages. #DFIR_Radar

    Post summary

    The post discloses the technical details of CVE-2025-27727, presents a full exploit chain, and confirms a patch was released in April 2025.

    101031.2K
    1.7K followersView on X
CPE platform detail21 entries

21 of 21 entries

PartVendorProductVersionTarget SWTarget HW
OSmicrosoftwindows_10_1507--x64
OSmicrosoftwindows_10_1507--x86
OSmicrosoftwindows_10_1607--x64
OSmicrosoftwindows_10_1607--x86
OSmicrosoftwindows_10_1809--x64
OSmicrosoftwindows_10_1809--x86
OSmicrosoftwindows_10_21h2---
OSmicrosoftwindows_10_22h2---
OSmicrosoftwindows_11_22h2---
OSmicrosoftwindows_11_23h2---
OSmicrosoftwindows_11_24h2---
OSmicrosoftwindows_server_2008--x64
OSmicrosoftwindows_server_2008--x86
OSmicrosoftwindows_server_2008r2-x64
OSmicrosoftwindows_server_2012---
OSmicrosoftwindows_server_2012r2--
OSmicrosoftwindows_server_2016---
OSmicrosoftwindows_server_2019---
OSmicrosoftwindows_server_2022---
OSmicrosoftwindows_server_2022_23h2---
OSmicrosoftwindows_server_2025---

Explore more